Free CAA Record Checker & Analyzer
CAA (Certificate Authority Authorization, RFC 8659) is a DNS record type that allows domain owners to specify which Certificate Authorities (CAs) are authorized to issue SSL/TLS certificates for their domain. By publishing CAA records, you prevent unauthorized CAs from issuing certificates, reducing the risk of fraudulently issued certificates being used in man-in-the-middle attacks. Our free CAA checker queries your domain's CAA records, validates the allowed CAs, checks policy flags like issuewild and iodef, and provides clear recommendations to strengthen your certificate issuance policy.
What This Tool Checks
Comprehensive analysis powered by Vysiro's scanning engines
CAA DNS record lookup and parsing
Allowed certificate authority validation
Wildcard issuance policy check (issuewild)
Incident reporting contact verification (iodef)
Critical flag detection and analysis
Parent domain CAA inheritance check
Multi-CA policy analysis
Certificate issuance risk assessment
How It Works
Get results in seconds with our automated scanning process
Enter your domain name in the scanner above
We query DNS for CAA records at your domain
Our engine parses issue, issuewild, and iodef tags
We validate allowed CAs against known authorities
We check for critical flags and policy gaps
You receive a detailed CAA analysis with recommendations
Frequently Asked Questions
Everything you need to know about caa record checker
What is a CAA record?
A CAA (Certificate Authority Authorization) record is a DNS resource record defined in RFC 8659 that specifies which Certificate Authorities (CAs) are permitted to issue SSL/TLS certificates for a domain. CAs are required to check CAA records before issuing certificates and must refuse issuance if they are not listed.
Why should I set up CAA records?
CAA records reduce the risk of unauthorized certificate issuance. Without CAA records, any CA can issue a certificate for your domain. By specifying allowed CAs, you limit the attack surface and make it harder for attackers to obtain fraudulent certificates through compromised or rogue CAs.
What is the difference between issue and issuewild?
The 'issue' tag specifies which CAs can issue regular (non-wildcard) certificates, while 'issuewild' specifies which CAs can issue wildcard certificates. If issuewild is not present, the issue tag applies to both. You can set issuewild to ';' (empty) to prohibit wildcard certificate issuance entirely.
What is the iodef tag in CAA?
The 'iodef' tag specifies a URL or email address where CAs should report certificate issuance policy violations. For example, iodef 'mailto:security@example.com' tells CAs to email you when someone attempts to get a certificate from an unauthorized CA. This provides valuable security alerting.
Do all CAs check CAA records?
Yes, since September 2017, all publicly trusted CAs are required to check CAA records before issuing certificates, per the CA/Browser Forum Ballot 187. If a CA is not listed in your CAA records, it must refuse to issue a certificate for your domain.
How do CAA records inherit from parent domains?
If no CAA records are found at the queried domain, the CA walks up the DNS tree checking parent domains. For example, if sub.example.com has no CAA records, the CA checks example.com. If example.com has CAA records, those apply. If no CAA records are found at any level, any CA may issue certificates.
Related Free Tools
Continue your domain security analysis
SSL Inspector
Analyze SSL/TLS certificates, expiration, and security configuration.
Use toolSSL Decoder
Decode and display SSL/TLS certificate details including subject, SANs, and chain info.
Use toolDNS Health
Full DNS configuration analysis and health scoring.
Use toolTrustScore
Get an instant composite trust score (0-1000) across 29 security categories.
Use toolGo Beyond Free Checks
Get continuous monitoring, automated fixes, proof packs, and API access. Protect your domains with Vysiro's agentless attack-surface monitor.